跳转到帖子

Red Hat: CVE-2023-25193: allows attackers to trigger O(n^2) growth via consecutive marks (Multiple Advisories)

recommended_posts

发布于
  • Members

Red Hat: CVE-2023-25193: allows attackers to trigger O(n^2) growth via consecutive marks (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
02/04/2023
Created
07/21/2023
Added
07/21/2023
Modified
01/28/2025

Description

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Solution(s)

  • redhat-upgrade-harfbuzz
  • redhat-upgrade-harfbuzz-debuginfo
  • redhat-upgrade-harfbuzz-debugsource
  • redhat-upgrade-harfbuzz-devel
  • redhat-upgrade-harfbuzz-devel-debuginfo
  • redhat-upgrade-harfbuzz-icu
  • redhat-upgrade-harfbuzz-icu-debuginfo
  • redhat-upgrade-java-11-openjdk
  • redhat-upgrade-java-11-openjdk-debuginfo
  • redhat-upgrade-java-11-openjdk-debugsource
  • redhat-upgrade-java-11-openjdk-demo
  • redhat-upgrade-java-11-openjdk-demo-fastdebug
  • redhat-upgrade-java-11-openjdk-demo-slowdebug
  • redhat-upgrade-java-11-openjdk-devel
  • redhat-upgrade-java-11-openjdk-devel-debuginfo
  • redhat-upgrade-java-11-openjdk-devel-fastdebug
  • redhat-upgrade-java-11-openjdk-devel-fastdebug-debuginfo
  • redhat-upgrade-java-11-openjdk-devel-slowdebug
  • redhat-upgrade-java-11-openjdk-devel-slowdebug-debuginfo
  • redhat-upgrade-java-11-openjdk-fastdebug
  • redhat-upgrade-java-11-openjdk-fastdebug-debuginfo
  • redhat-upgrade-java-11-openjdk-headless
  • redhat-upgrade-java-11-openjdk-headless-debuginfo
  • redhat-upgrade-java-11-openjdk-headless-fastdebug
  • redhat-upgrade-java-11-openjdk-headless-fastdebug-debuginfo
  • redhat-upgrade-java-11-openjdk-headless-slowdebug
  • redhat-upgrade-java-11-openjdk-headless-slowdebug-debuginfo
  • redhat-upgrade-java-11-openjdk-javadoc
  • redhat-upgrade-java-11-openjdk-javadoc-zip
  • redhat-upgrade-java-11-openjdk-jmods
  • redhat-upgrade-java-11-openjdk-jmods-fastdebug
  • redhat-upgrade-java-11-openjdk-jmods-slowdebug
  • redhat-upgrade-java-11-openjdk-slowdebug
  • redhat-upgrade-java-11-openjdk-slowdebug-debuginfo
  • redhat-upgrade-java-11-openjdk-src
  • redhat-upgrade-java-11-openjdk-src-fastdebug
  • redhat-upgrade-java-11-openjdk-src-slowdebug
  • redhat-upgrade-java-11-openjdk-static-libs
  • redhat-upgrade-java-11-openjdk-static-libs-fastdebug
  • redhat-upgrade-java-11-openjdk-static-libs-slowdebug
  • redhat-upgrade-java-17-openjdk
  • redhat-upgrade-java-17-openjdk-debuginfo
  • redhat-upgrade-java-17-openjdk-debugsource
  • redhat-upgrade-java-17-openjdk-demo
  • redhat-upgrade-java-17-openjdk-demo-fastdebug
  • redhat-upgrade-java-17-openjdk-demo-slowdebug
  • redhat-upgrade-java-17-openjdk-devel
  • redhat-upgrade-java-17-openjdk-devel-debuginfo
  • redhat-upgrade-java-17-openjdk-devel-fastdebug
  • redhat-upgrade-java-17-openjdk-devel-fastdebug-debuginfo
  • redhat-upgrade-java-17-openjdk-devel-slowdebug
  • redhat-upgrade-java-17-openjdk-devel-slowdebug-debuginfo
  • redhat-upgrade-java-17-openjdk-fastdebug
  • redhat-upgrade-java-17-openjdk-fastdebug-debuginfo
  • redhat-upgrade-java-17-openjdk-headless
  • redhat-upgrade-java-17-openjdk-headless-debuginfo
  • redhat-upgrade-java-17-openjdk-headless-fastdebug
  • redhat-upgrade-java-17-openjdk-headless-fastdebug-debuginfo
  • redhat-upgrade-java-17-openjdk-headless-slowdebug
  • redhat-upgrade-java-17-openjdk-headless-slowdebug-debuginfo
  • redhat-upgrade-java-17-openjdk-javadoc
  • redhat-upgrade-java-17-openjdk-javadoc-zip
  • redhat-upgrade-java-17-openjdk-jmods
  • redhat-upgrade-java-17-openjdk-jmods-fastdebug
  • redhat-upgrade-java-17-openjdk-jmods-slowdebug
  • redhat-upgrade-java-17-openjdk-slowdebug
  • redhat-upgrade-java-17-openjdk-slowdebug-debuginfo
  • redhat-upgrade-java-17-openjdk-src
  • redhat-upgrade-java-17-openjdk-src-fastdebug
  • redhat-upgrade-java-17-openjdk-src-slowdebug
  • redhat-upgrade-java-17-openjdk-static-libs
  • redhat-upgrade-java-17-openjdk-static-libs-fastdebug
  • redhat-upgrade-java-17-openjdk-static-libs-slowdebug

References

  • CVE-2023-25193
  • RHSA-2023:4157
  • RHSA-2023:4158
  • RHSA-2023:4159
  • RHSA-2023:4164
  • RHSA-2023:4169
  • RHSA-2023:4170
  • RHSA-2023:4175
  • RHSA-2023:4177
  • RHSA-2023:4233
  • RHSA-2024:2410
  • RHSA-2024:2980
View more
  • 查看数 697
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…